Latest CVE Feed
-
4.3
MEDIUMCVE-2008-2694
Cross-site scripting (XSS) vulnerability in search.php in phpInv 0.8.0 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.... Read more
Affected Products : phpinv- Published: Jun. 13, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-0627
Cross-site scripting (XSS) vulnerability in Clever Copy 2.0, 2.0a, and 3.0 allows remote attackers to inject arbitrary web script or HTML via the (1) Referer or (2) X-Forwarded-For headers in an HTTP request, which are not properly handled when the admini... Read more
Affected Products : clever_copy- Published: Feb. 09, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2024-0456
An authorization vulnerability exists in GitLab versions 14.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. An unauthorized attacker is able to assign arbitrary users to MRs that they created within the project... Read more
Affected Products : gitlab- Published: Jan. 26, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-0515
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the remove_from_compare function. This makes it... Read more
Affected Products : royal_elementor_addons- Published: Feb. 29, 2024
- Modified: Jan. 08, 2025
-
4.3
MEDIUMCVE-2006-0609
Cross-site scripting (XSS) vulnerability in add.php in Hinton Design phphd 1.0 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.... Read more
Affected Products : phphd- Published: Feb. 08, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2024-0513
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the remove_from_wishlist function. This makes i... Read more
Affected Products : royal_elementor_addons- Published: Feb. 29, 2024
- Modified: Jan. 08, 2025
-
4.3
MEDIUMCVE-2008-2773
Cross-site scripting (XSS) vulnerability in the Taxonomy Image module 5.x before 5.x-1.3 and 6.x before 6.x-1.3, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : taxonomy_image_module- Published: Jun. 18, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-3219
The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not "prevent use of the object HTML tag in administrator input," which has unknown impact and attack vectors, probably related to an insufficient cross-site scripting (XSS) pro... Read more
- Published: Jul. 18, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2800
Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 allow remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via vectors involving (1) an event handler attached to an outer window, (2) a SCRIPT element... Read more
- Published: Jul. 07, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2720
Cross-site scripting (XSS) vulnerability in Menalto Gallery before 2.2.5 allows remote attackers to inject arbitrary web script or HTML via the (1) host and (2) path components of a URL.... Read more
Affected Products : gallery- Published: Jun. 16, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-6588
Cross-site scripting (XSS) vulnerability in PHCDownload 1.10 allows remote attackers to inject arbitrary web script or HTML via the username field in an unspecified component. NOTE: the provenance of this information is unknown; the details are obtained ... Read more
Affected Products : phcdownload- Published: Dec. 28, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2711
fetchmail 6.3.8 and earlier, when running in -v -v (aka verbose) mode, allows remote attackers to cause a denial of service (crash and persistent mail failure) via a malformed mail message with long headers, which triggers an erroneous dereference when us... Read more
Affected Products : fetchmail- Published: Jun. 16, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-16518
An issue was discovered on Swell Kit Mod devices that use the Vandy Vape platform. An attacker may be able to trigger an unintended temperature in the victim's mouth and throat via Bluetooth Low Energy (BLE) packets that specify large power or voltage val... Read more
- Published: Sep. 23, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-2696
Exiv2 0.16 allows user-assisted remote attackers to cause a denial of service (divide-by-zero and application crash) via a zero value in Nikon lens information in the metadata of an image, related to "pretty printing" and the RationalValue::toLong functio... Read more
Affected Products : exiv2- Published: Jun. 13, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-2730
Mozilla Network Security Services (NSS) before 3.19.1, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and other products, does not properly perform Elliptical Curve Cryptography (ECC) multiplications, which make... Read more
- Published: Jul. 06, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-3102
Unspecified vulnerability in the linux_audit_record_event function in OpenSSH 4.3p2, as used on Fedora Core 6 and possibly other systems, allows remote attackers to write arbitrary characters to an audit log via a crafted username. NOTE: some of these de... Read more
- Published: Oct. 18, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-2650
The OLE2 parser in Clam AntiVirus (ClamAV) allows remote attackers to cause a denial of service (resource consumption) via an OLE2 file with (1) a large property size or (2) a loop in the FAT file block chain that triggers an infinite loop, as demonstrate... Read more
- Published: May. 14, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-0257
Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) content of indexed files to the (a) Index... Read more
Affected Products : typo3- Published: Jan. 22, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-0958
Cross-site scripting (XSS) vulnerability in func.inc.php in ZoneO-Soft freeForum before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the (1) name and (2) subject parameters.... Read more
Affected Products : freeforum- Published: Mar. 02, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2007-6558
TotalPlayer 3.0 allows user-assisted remote attackers to cause a denial of service (application crash) via a large .m3u file. NOTE: this might be a duplicate of CVE-2006-6288.... Read more
Affected Products : totalplayer- Published: Dec. 28, 2007
- Modified: Apr. 09, 2025